View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Certighost AD Exploit and Check Point 0-day Actively Exploited

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Certighost AD Exploit and Check Point 0-day Actively Exploited
    Multiple critical vulnerabilities and active exploits affected enterprise security products and infrastructure this week.
    • Active Directory Certighost flaw (CVE-2026-54121) lets low-privilege users impersonate Domain Controllers
    • Check Point SmartConsole authentication bypass (CVE-2026-16232) actively exploited for admin access
    • HTTP/2 DoS bugs (CVE-2026-44909, CVE-2026-59173, CVE-2026-59762) cause server memory exhaustion
    • Notepad++ plugin hijacked via phishing, deploying trojan DLLs for persistence and payload delivery
    • Palo Alto PAN-OS authentication bypass (CVE-2026-0257) exploited to deploy ransomware and steal AD data
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Claude AI Shared Chats Exposed in Google Search Results
    Claude AI shared chat links were publicly indexed by Google, exposing sensitive conversations.
    • Applies to Anthropic Claude AI users sharing conversations via public URLs
    • Shared chats included legal advice, engineering work, and personal discussions
    • Exposure occurred because shared links lacked noindex tags, allowing Google to index them
    • Discovery made via Reddit; hundreds of chats were accessible without direct links
    • Google results largely removed after issue surfaced, but saved URLs may still grant access
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check